PoC Index

CVE-2019-11707

KEVHIGH 8.8EPSS 37.7%

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
37.70% chance of exploitation in the next 30 days, 98th percentile
CISA KEV
added 2022-05-23
Published
2019-07-23
Updated
2025-10-21

Proof-of-concept exploits (6)

ExploitDB entries (2)

References

Related